From: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
To: linux-cve-announce@vger.kernel.org
Cc: Greg Kroah-Hartman <gregkh@kernel.org>
Subject: CVE-2026-63808: exfat: fix potential use-after-free in exfat_find_dir_entry()
Date: Sun, 19 Jul 2026 14:02:25 +0200 [thread overview]
Message-ID: <2026071902-CVE-2026-63808-263b@gregkh> (raw)
From: Greg Kroah-Hartman <gregkh@kernel.org>
Description
===========
In the Linux kernel, the following vulnerability has been resolved:
exfat: fix potential use-after-free in exfat_find_dir_entry()
In exfat_find_dir_entry(), the buffer_head obtained from
exfat_get_dentry() is released with brelse(bh) before the fall-through
TYPE_EXTEND branch reads the directory entry through ep (which points
into bh->b_data):
brelse(bh);
if (entry_type == TYPE_EXTEND) {
...
len = exfat_extract_uni_name(ep, entry_uniname);
...
}
After brelse() drops our reference, nothing guarantees that the
underlying page backing bh->b_data remains valid for the subsequent
exfat_extract_uni_name() read. This is the same pattern fixed in
commit fc961522ddbd ("exfat: Fix potential use after free in
exfat_load_upcase_table()").
Move brelse(bh) so it runs after ep is no longer dereferenced on
each branch.
Confirmed on QEMU x86_64 with CONFIG_KASAN=y + CONFIG_DEBUG_PAGEALLOC=y
+ CONFIG_PAGE_POISONING=y on linux-next, using a crafted exFAT image
(long filename with same-hash collisions forcing the TYPE_EXTEND path).
With a debug-only invalidate_bdev() inserted between brelse(bh) and
the ep read to make the stale-deref window deterministic, the
unpatched kernel faults:
BUG: KASAN: use-after-free in exfat_find_dir_entry+0x133b/0x15a0
BUG: unable to handle page fault for address: ffff88801a5fa0c2
Oops: 0000 [#1] SMP DEBUG_PAGEALLOC KASAN NOPTI
RIP: 0010:exfat_find_dir_entry+0x1188/0x15a0
With this patch applied, the same instrumented harness completes
cleanly under the same sanitizer stack. I have not reproduced a
crash on an uninstrumented kernel under ordinary reclaim; the
instrumented A/B establishes the lifetime violation and that the
patch closes it, not an unaided triggerability claim.
The Linux kernel CVE team has assigned CVE-2026-63808 to this issue.
Affected and fixed versions
===========================
Issue introduced in 5.7 with commit ca06197382bde0a3bc20215595d1c9ce20c6e341 and fixed in 5.10.260 with commit e6f1a11cfb808441a43ffae9b476cc135732cd27
Issue introduced in 5.7 with commit ca06197382bde0a3bc20215595d1c9ce20c6e341 and fixed in 5.15.211 with commit e48f413c2815787b8cade2795e194e3c4cd782ef
Issue introduced in 5.7 with commit ca06197382bde0a3bc20215595d1c9ce20c6e341 and fixed in 6.1.177 with commit 06c4e1e9967d332ac33ba38b7819851089ff9359
Issue introduced in 5.7 with commit ca06197382bde0a3bc20215595d1c9ce20c6e341 and fixed in 6.6.144 with commit 8e0abc17fbd7e305802e84fe98b4950d50f9c433
Issue introduced in 5.7 with commit ca06197382bde0a3bc20215595d1c9ce20c6e341 and fixed in 6.12.95 with commit 4d101016d5e587f820b3ae2d5bb6770d86342649
Issue introduced in 5.7 with commit ca06197382bde0a3bc20215595d1c9ce20c6e341 and fixed in 6.18.38 with commit adfacfbaeae2cb760f492357cc36b41f84ef7f86
Issue introduced in 5.7 with commit ca06197382bde0a3bc20215595d1c9ce20c6e341 and fixed in 7.1.3 with commit 708b97e792945d3e4653939fd3405d71a61ad065
Issue introduced in 5.7 with commit ca06197382bde0a3bc20215595d1c9ce20c6e341 and fixed in 7.2-rc1 with commit 3f5f8ee9917cc2b9076ac533492d8a200edcabb8
Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.
Unaffected versions might change over time as fixes are backported to
older supported kernel versions. The official CVE entry at
https://cve.org/CVERecord/?id=CVE-2026-63808
will be updated if fixes are backported, please check that for the most
up to date information about this issue.
Affected files
==============
The file(s) affected by this issue are:
fs/exfat/dir.c
Mitigation
==========
The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes. Individual
changes are never tested alone, but rather are part of a larger kernel
release. Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all. If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
https://git.kernel.org/stable/c/e6f1a11cfb808441a43ffae9b476cc135732cd27
https://git.kernel.org/stable/c/e48f413c2815787b8cade2795e194e3c4cd782ef
https://git.kernel.org/stable/c/06c4e1e9967d332ac33ba38b7819851089ff9359
https://git.kernel.org/stable/c/8e0abc17fbd7e305802e84fe98b4950d50f9c433
https://git.kernel.org/stable/c/4d101016d5e587f820b3ae2d5bb6770d86342649
https://git.kernel.org/stable/c/adfacfbaeae2cb760f492357cc36b41f84ef7f86
https://git.kernel.org/stable/c/708b97e792945d3e4653939fd3405d71a61ad065
https://git.kernel.org/stable/c/3f5f8ee9917cc2b9076ac533492d8a200edcabb8
reply other threads:[~2026-07-19 12:04 UTC|newest]
Thread overview: [no followups] expand[flat|nested] mbox.gz Atom feed
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=2026071902-CVE-2026-63808-263b@gregkh \
--to=gregkh@linuxfoundation.org \
--cc=cve@kernel.org \
--cc=gregkh@kernel.org \
--cc=linux-cve-announce@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.